首页> 外国专利> INCIDENT TRIAGE SCORING ENGINE

INCIDENT TRIAGE SCORING ENGINE

机译:突发事件评分引擎

摘要

#$%^&*AU2017254913B220190530.pdf#####ABSTRACT Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for incident response are disclosed. In one aspect, a system includes a cognitive engine that is configured to receive data identifying actions performed in response to a computer security threat. Based on the data identifying the actions performed in response to the computer security threat, the system generates one or more workflows and a particular workflow that are associated with the computer security threat and that each identify one or more actions to remediate the computer security threat. The system also includes a scoring system and event triage engine that is configured to analyze the actions of the one or more workflows and of the particular workflow, and based on analyzing the actions of the one or more workflows and of the particular workflow, select a primary workflow as a workflow to respond to the computer security threat. The system also includes an automated incident investigation engine that is configured to receive an alert that identifies the computer security threat, and process the computer security threat according to the primary workflow that is associated with the computer security threat and that identifies one or more actions to remediate the computer security threat.1/12 e~a) cli0-CC a)~ LL. o0 4- c CU a CUC CU Lo a)5. o0) .9 C4U 0p -j. _0 0 ~ 00 0 a)~ CU4 L------------------------------------ -------
机译:#$%^&* AU2017254913B220190530.pdf #####抽象方法,系统和装置,包括编码在计算机上的计算机程序公开了用于事件响应的计算机存储介质。一方面,一种系统包括认知引擎,该认知引擎配置为接收识别执行的动作的数据应对计算机安全威胁。根据识别动作的数据响应计算机安全威胁而执行的系统将生成一个或多个与计算机安全威胁相关的工作流程和特定工作流程并且每个都标识一个或多个纠正计算机安全威胁的措施。的系统还包括评分系统和配置为进行分析的事件分类引擎一个或多个工作流程以及特定工作流程的操作,并基于在分析一个或多个工作流程以及特定工作流程的操作后,选择一个主工作流程作为响应计算机安全威胁的工作流程。该系统还包括自动事件调查引擎,该引擎配置为接收警报,识别计算机安全威胁,并根据以下信息处理计算机安全威胁到与计算机安全威胁相关联并标识纠正计算机安全威胁的一项或多项操作。1/12e〜a)cli0-抄送a)〜二。004一铜中国人民大学CU Lo a)5。 o0).9C4U0p-j _00>〜000 a)〜CU4L ------------------------------------ -------

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号